Many charities will have seen reports this week of a cybersecurity incident affecting Beacon CRM, a widely used customer relationship management platform in the charity sector. According to Beacon, unauthorised access to its systems resulted in copies of customer database backups being obtained by a third party, potentially affecting data held on behalf of over 1,000 charities.
An organisation using Beacon CRM is likely to be the controller of any personal data that it stores on the platform. The key question is not therefore simply whether a supplier has suffered a breach, but whether your organisation has its own legal and regulatory obligations arising from the incident.
What should charities be doing now?
1. Assess whether a personal data breach has occurred
Charities that use Beacon CRM should urgently establish:
- What personal data was stored within Beacon CRM;
- Whether that data is likely to have been accessed or copied;
- The categories and volume of individuals affected; and
- The potential impact on those individuals.
Although Beacon has provided information to customers (and has noted in particular that customers may want to assume that all of the data on Beacon CRM has been downloaded), each charity remains responsible for assessing the risks to the individuals whose data it controls.
2. Consider whether notification to the ICO is required
Under the UK GDPR, organisations must notify the ICO of a personal data breach unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. The notification must generally be made within 72 hours of the organisation becoming aware of the breach. If any of the affected data is special category (‘sensitive’) data, then it is highly likely that it will need to be reported, but it is also likely that a report will need to be made if, for example, individuals’ contact details have been compromised, given that they may receive unwanted emails or be subject to phishing or other emails. The ICO has confirmed it is aware of the Beacon incident and is receiving reports from affected organisations.
Charities should document their decision-making process, even where they conclude that notification is not required.
3. Consider whether affected individuals need to be informed
Where a breach is likely to result in a high risk to individuals’ rights and freedoms, organisations may be required to notify affected individuals without undue delay.
The appropriate communication strategy will depend on the nature of the compromised data and the people that have been affected e.g. customers, servicer users or supporters. Careful drafting is important to ensure communications are clear, accurate and appropriate.
4. Review whether a Serious Incident Report should be submitted
Trustees should consider whether the incident constitutes a serious incident that should be reported to the Charity Commission. Charity Commission guidance states that data breaches should generally be reported to it, including where a breach has been reported to the ICO.
Charities should ensure that the issue is escalated appropriately and that decisions are properly recorded.
How we can help
Our Data & Privacy team is currently supporting charities affected by this incident. We can assist with:
- Rapid breach assessments and risk analysis;
- ICO breach notifications and follow-up correspondence with the ICO;
- Supporter, donor, volunteer and beneficiary communications;
- Charity Commission Serious Incident Reports;
- Advice to trustees on governance and regulatory obligations; and
- Managing communications with regulators and other stakeholders.
If your charity uses Beacon CRM and would like support in assessing its legal and regulatory obligations, please contact Hannah Lyons or Rayhaan Vankalwala for urgent advice.
The material in this article is provided for guidance and general information only and is not intended to constitute legal or other professional advice upon which you should rely. In particular, the information should not be used as a substitute for a full and proper consultation with a suitably qualified professional. Please do contact the Bates Wells team if you require further advice.